Applicability starts with the service
Compare the precise entity and service category in Annex I with the organisation’s actual activity. Review size-related rules, exceptions and the law of the relevant Member State before concluding that an entity is in or out of scope.
Implementation considerations
- Map operational service boundaries
- Assess continuity of scheduling and control systems
- Clarify incident escalation and partner dependencies
Obligations to review
For in-scope entities, examine cybersecurity risk-management measures, management oversight and the reporting of significant incidents, including the national rules and any sector-specific EU measures.
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.